PT-2026-92355 · Google · Pixel 11+7

CVE-2026-58704

·

Published

2026-09-15

·

Updated

2026-10-03

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Pixel versions 6 through 11, Pixel Tablet, and Pixel Fold (affected versions prior to security patch level 2026-09-05)
Description A high-severity logic error in the Cellular Modem component of Google Pixel devices allows for a permission bypass. This flaw enables a remote attacker located on an adjacent or proximal radio network to escalate privileges to elevated system or modem execution contexts. The issue is a zero-click flaw, meaning it requires no user interaction to exploit. It has been observed in limited, targeted real-world attacks, often associated with commercial spyware or state-aligned surveillance targeting high-value individuals. Technical exploitation occurs within baseband memory buffers and involves bypassing internal permission gates via the modem's inter-process communication (IPC) logic.
Recommendations Update all Google Pixel hardware to security patch level 2026-09-05 or later. As a temporary mitigation in high-threat environments, enable Airplane Mode and use trusted Wi-Fi networks to restrict proximal RF exposure. For high-risk targets, consider enabling Android Advanced Protection or Lockdown Mode.

Fix

DoS

RCE

LPE

Improper Authorization

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14807
CVE-2026-58704

Affected Products

Pixel 10
Pixel 11
Pixel 6
Pixel 7
Pixel 8
Pixel 9
Pixel Fold
Pixel Tablet